5.9
CVE-2017-5915
- EPSS 0.12%
- Veröffentlicht 05.05.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Version3.10.0 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Version3.10.1 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Version3.10.2 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Version3.10.3 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Version3.10.4 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Ksa Version2.0.0 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Ksa Version2.0.1 SwPlatformiphone_os
Emirates Nbd Bank P.J.S.C ≫ Emirates Nbd Ksa Version2.1.0 SwPlatformiphone_os
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.28 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.